Description
WordPress Plugin Easy Digital Downloads-Simple eCommerce for Selling Digital Files is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently reset the password of any user, including administrator. WordPress Plugin Easy Digital Downloads-Simple eCommerce for Selling Digital Files versions 3.1 - 3.1.1.4.1 are vulnerable.
Remediation
Update to plugin version 3.1.1.4.2 or latest
References
Related Vulnerabilities
SharePoint Resource Management Errors Vulnerability (CVE-2015-0064)
WordPress Plugin WP-Filebase Download Manager Multiple Unspecified Vulnerabilities (0.2.9.24)
Oracle Database Server CVE-2011-0792 Vulnerability (CVE-2011-0792)
WordPress Plugin 10WebAnalytics Cross-Site Request Forgery (1.2.8)
WordPress Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability (CVE-2022-3590)